Alina 3 4 POS Malware
Alina 3 4 POS Malware The malware come from: http://vxvault.siri-urz.net/ViriFiche.php?ID=23179 Hosted on the site of a deputy. GetPCname: Create a mutex: Create /%appdata%/java.exe If the malware cant he will try with different name (jusched.exe, jucheck.exe, desktop.exe, dwm.exe, win-firewall.exe, adobeflash.exe) If all names are take and in read only mode the malware is trapped on infinit loop :))) Write the file: and if he fail to write he will Copy it: Add a registry persistence: Launch the process: Encode something (ive not checked what) Call the C&C And fail because the first is dead, so retry with 208.98.63.228 Backend info: 208.98.63.228: OrgName: Sharktech OrgId: SHARK-7 Address: 100 Pinehurst Ct. City: Missoula StateProv: MT PostalCode: 59803 Country: US http://xxx.98.63.228/main.php http://xxx.98.63.228/info.php http://xxx.98.63.228/test.php http://xxx.98.63.228/test2.php http://xxx.98.63.228/api.php http://xxx.98.63.228/config.php http://xxx.98.63.228/autoupdate.php ht...